From owner-freebsd-security Wed Aug 8 15:41:45 2001 Delivered-To: freebsd-security@freebsd.org Received: from wrath.cs.utah.edu (wrath.cs.utah.edu [155.99.198.100]) by hub.freebsd.org (Postfix) with ESMTP id 2F7CC37B41C; Wed, 8 Aug 2001 15:41:40 -0700 (PDT) (envelope-from danderse@cs.utah.edu) Received: from faith.cs.utah.edu (faith.cs.utah.edu [155.99.198.108]) by wrath.cs.utah.edu (8.11.1/8.11.1) with ESMTP id f78Mfc911115; Wed, 8 Aug 2001 16:41:38 -0600 (MDT) From: David G Andersen Received: (from danderse@localhost) by faith.cs.utah.edu (8.11.1/8.11.1) id f78Mfcr11144; Wed, 8 Aug 2001 16:41:38 -0600 (MDT) Message-Id: <200108082241.f78Mfcr11144@faith.cs.utah.edu> Subject: Re: finger/fingerd & home directory permissions To: bright@mu.org (Alfred Perlstein) Date: Wed, 8 Aug 2001 16:41:38 -0600 (MDT) Cc: danderse@cs.utah.edu (David G Andersen), yar@FreeBSD.ORG (Yar Tikhiy), security@FreeBSD.ORG In-Reply-To: <20010808173947.I85642@elvis.mu.org> from "Alfred Perlstein" at Aug 08, 2001 05:39:47 PM X-Mailer: ELM [version 2.5 PL2] MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org Lo and behold, Alfred Perlstein once said: > > > > a) Add a command-line option to finger(1) and fingerd(8) telling > > > them not to reveal user information if the user's homedir is > > > protected. > > > > > > b) Similar to a), but hide such users by default. > > > > > > c) Don't bother at all :-) > > > > > > Personally, I'd prefer b) since it's most secure and seems to break > > > nothing. Do I overlook any complications? > > > > Yes - it breaks the semantics of the existing fingerds that > > people are used to. It's a gratuitious change with little benefit > > that would simply confuse people who have a reasonable expectation > > about what the default behavior of 'finger' should be. Don't do (b). > > Actually, I'd prefer (b) if it was a command line option. > > ie, not the default. And this differs from suggestion (a) in exactly what way? :) -Dave To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message